Enterprise Workloads love running on AWS! In this session come and learn about the ways that enterprises have successfully migrated their critical Microsoft, SAP and Oracle workloads to AWS to improve operational performance.
Speaker:
Danny Jenkins, Solutions Architect, Amazon Web Services
2. Why Are We Here?
• What is an enterprise application?
• Customers already running these on AWS
• Why would I run these workloads on AWS?
• Example architectures
• Best practice guidance
3. What is an Enterprise Application?
Any application that is core to running your business
• E-mail and collaboration systems
• Enterprise Resource Planning (ERP)
• Customer Relationship Management (CRM)
• Data Warehouse & Reporting
• Human Capital Management
• Procurement
• Warehousing & Logistics
• + Many more
4. Enterprise Applications on AWS
Vendor Applications
SAP Business Suite, Netweaver, BusinessObjects, B1, HANA
Oracle eBusiness, PeopleSoft, Siebel, JDE, Database 11g/12c
Microsoft Active Directory, SharePoint, Exchange, Dynamics, SQL Server
IBM Websphere, DataStage
Infor LN, M3, Syteline, Lawson
AWS customers run many business applications
Companies of all sizes from SMB to large enterprises run business
applications on AWS
5. Enterprise Customers Running on AWS
General Electric Capital One
BMW
Johnson &
Johnson
Merck
Nordstrom
“There is no public cloud infrastructure provider
that has more robust enterprise capabilities.”
Marc Benioff, Chairman & CEO, Salesforce
7. • Needed a simplified way for detailed cross-
functional reporting
• Proof of Concept (PoC) was to be delivered within
one month
• > 10x reduction in run time
• > 50% reduction in cost of delivery
• Scaled HANA production system in an hour
• AWS “made SAP fun !”
Fairfax Media is one of the largest media
companies in Australia and New Zealand
We delivered the PoC on time
and budget. And within three
months we had our production
system live. After six months,
our production system was at
capacity so we upgraded from
a 244 GB to a 2 TB system
within one hour.
Diego Lombardini
Head of Finance Systems, Fairfax Media
”
“
Fairfax Media Uses AWS for BW4/HANA Production
8. Seaco Uses AWS to Improve SAP Performance
• Needed a faster solution to host its SAP
applications
• Moved its previously hosted datacenter
solution to AWS
• Improved the performance of its SAP
applications by nearly 90%
• Saved more than 50% in IT
infrastructure and maintenance costs.
• Reduced its monthly billing-process
time by 75%
Our performance of SAP on AWS
is off the scale. We reduced our
monthly billing cycle from four days
to one day and have significantly
reduced our overall annual IT
costs.
Carlos Galiano
Chief Information Officer, Seaco Global Ltd.
”
“
Seaco Global Ltd. is the world’s largest sea container
leasing company with assets in excess of $6 billion.
9. Why AWS?
Breadth of services
Pace of innovation
Established partner ecosystem
13. AWS Regions and Availability Zones
Availability
Zone
Availability
Zone
Availability
Zone
Region
14. Single-AZ Availability Zone A
Private SubnetPublic Subnet
NAT
APPWEB
App
Server
IIS
Server
Availability Zone B
Users
DB
DB
Server
15. Availability Zone A
Private SubnetPublic Subnet
NAT
APPWEB
App
Server
IIS
Server
Users
DB
DB
Server
Availability Zone B
Private SubnetPublic Subnet
NAT
APPWEB
App
Server
IIS
Server
DB
DB
Server
Multi-AZ Model
16. Availability Zone A
Private SubnetPublic Subnet
NAT
APPWEB
App
Server
IIS
Server
Users
DB
DB
Server
Availability Zone B
Private SubnetPublic Subnet
NAT
APPWEB
App
Server
IIS
Server
DB
DB
Server
Multi-AZ Model
(Failed AZ)
23. Directory Services
• Managed MicrosoftAD or Run your own
• Integrate with on-premises AD
• Integrate with Office 365 using AADConnect
• Consume other services such as Workspaces, Workdocs and Chime
• Federated login to the AWS console and role based access to AWS resources
WorkDocs
Secure enterprise
document collaboration
WorkSpaces
Virtual desktops
Secure access from
anywhere
Central sync, document feedback
Secure access from anywhere
S3
WorkSpaces Application
Manager
Virtual applications
Centralised application
deployment
Chime
Real-time, unified communications
service that transforms meetings
Fully managed
Communications service
Directory Service
Managed directories
Simple AD, AD Connector, Microsoft AD
24. Directory – Federated Login
1User browses to idP
Portal / Identity Provider (idP)
LDAP identity
store
User Browser
AWS SSO Endpoint
STS Service
AWS Services
2
3 4
5
6
7
IdP returns SAML
assertion
User sent to AWS
Management console
Your organisation (Identity provider) AWS (Service Provider)
25. Single domain extended to multiple sites
Availability Zone B
Private subnet
DC4
Corporate Network
Munich
DC1
Berlin
DC2
Cost 50
Availability Zone A
Private subnet
DC3
Cost 10
company.local
company.local
One single identity, data center extension mode
(rely on Active Directory sites, read-only or not)
VPN
AWS Direct
Connect
26. One subdomain per site
Availability Zone B
Private subnet
DC4
Corporate Network
Munich
DC1
Berlin
DC2
company.local
Availability Zone A
Private subnet
DC3
cloud.company.local
Isolated subset of the directory, single identity for users
(Active Directory domains in a single forest)
VPN
AWS Direct
Connect
27. One forest per site and trust
Availability Zone B
Private subnet
DC4
Corporate Network
Munich
DC1
Berlin
DC2Availability Zone A
Private subnet
DC3 company.local
company.cloud
Separate directories, single identity
(Cross-forest/resource forest with trust)
AWS Directory Service
company.cloud
VPN
AWS Direct
Connect
28. SAP Solutions Certified on AWS
• SAP Business Suite
• SAP Business All-in-One (A1)
• SAP Netweaver
• SAP HANA Platform
• SAP BusinessObjects BI
• SAP Mobile Platform
• SAP Business One
• SAP Rapid Deployment Solutions
SAP Note 1656099 has latest information regarding SAP products and
platform supported on AWS
Solutions
29. SAP on AWS Key Benefits
Fully tested & certified by SAP Support
Leverage multi-AZ for production workloads
Wide choice of EC2 & EBS volume options
S3 provides 99.999999999% durability
Enterprise-level security
Pricing, capacity management, pace of innovation
Certified Solution
High Availability
High Performance
Durability
Security
Agility & Flexibility
31. SAP Production HA Architecture
Customer Network
Users
On-Premises
Systems
Private Subnet
Availability Zone A Availability Zone B
VPN or
Direct Connect
Private Subnet
App1
DB
AppN
ASCS
App1
DB
AppN
ASCS
(ENQ)
Session State
DB Replication
EBS SSD EBS SSD
SAP Production
33. Oracle Workload
Availability Zone BAvailability Zone B
Private SubnetPrivate SubnetPublic SubnetPublic Subnet
NATNAT
APPAPPWEBWEB
App
Server
App
Server
Web
Server
Web
Server
DBDB
Oracle Stand
By DB
Oracle Stand
By DB
Availability Zone B
Private SubnetPublic Subnet
NAT
APPWEB
App
Server
Web
Server
DB
Oracle Stand
By DB
Availability Zone A
Private SubnetPublic Subnet
NAT
APPWEB
App
Server
Web
Server
DB
Oracle
Primary DB
Users
Backups in S3
34. Oracle Secure Backup (OSB) allows customers to backup Oracle Databases
directly to Amazon S3 using RMAN
Data is compressed and encrypted in flight using Oracle Advanced Security
S3 provides high durability & encryption at rest
Simplify Backups with OSB Cloud Module
Oracle Secure
Backup Cloud
Module
Amazon S3
RMAN
Compression
Encryption
Database
35. Knowledge check
What is CloudFormation?
instances
Application
Load Balancer
Use Cases for
CloudFormation
• Deploy SOE image for new
installations in minutes
• Bootstrap instance to auto install
pre-requisite packages
• Clone production for isolated
error analysis
• Setup disaster recovery environment
across Regions
• Can be version controlled,
is consistent and fully automated
• Go global in minutes
Original stack
JSON
or YAML
Template
S3 Bucket
Duplicated stack
instances
Application
Load Balancer
S3 Bucket
36. Microsoft Enterprise Accelerator
Availability Zone B
Private SubnetPublic Subnet
NAT
LIN2EX2
Lync
Server
Exchange
Server
DB2
SQL
Server
Availability Zone A
Private SubnetPublic Subnet
NAT
LIN1EX1
Lync
Server
Exchange
Server
DB1
SQL
Server
Users
RDG
RDG
SP2
Sharepoint
Server
SP1
Sharepoint
Server
DC2
Active
Directory
DC1
Active
Directory
LE2
LE2
Remote Admin
EE1
EE1
NAT, SP and
Exchange Edge
NAT, SP and
Exchange Edge
https://docs.aws.amazon.com/quickstart/latest/accelerator-msservers/welcome.html
37. Microsoft Enterprise Accelerator
Availability Zone B
Private SubnetPublic Subnet
NAT
LIN2EX2
Lync
Server
Exchange
Server
DB2
SQL
Server
Availability Zone A
Private SubnetPublic Subnet
NAT
LIN1EX1
Lync
Server
Exchange
Server
DB1
SQL
Server
RDG
RDG
SP2
Sharepoint
Server
SP1
Sharepoint
Server
DC2
Active
Directory
DC1
Active
Directory
LE2
LE2
EE1
EE2
NAT, SP and
Exchange Edge
NAT, SP and
Exchange Edge
• Single VPC for integrated
cross-server experience
• Multi-AZ for High Availability
across all servers
• DMZ subnet for management
• Private subnet for app
servers
• Ability to Connect to on-
premises through Direct
Connect
AWS Infrastructure
https://docs.aws.amazon.com/quickstart/latest/accelerator-msservers/welcome.html
38. Microsoft Enterprise Accelerator
Availability Zone B
Private SubnetPublic Subnet
NAT
LIN2EX2
Lync
Server
Exchange
Server
DB2
SQL
Server
Availability Zone A
Private SubnetPublic Subnet
NAT
LIN1EX1
Lync
Server
Exchange
Server
DB1
SQL
Server
RDG
RDG
SP2
Sharepoint
Server
SP1
Sharepoint
Server
DC2
Active
Directory
DC1
Active
Directory
LE2
LE2
EE1
EE2
NAT, SP and
Exchange Edge
NAT, SP and
Exchange Edge
• Exchange DAG architecture
• Lync Paired Pool architecture
• SQL Server AlwaysOn
architecture for SharePoint
• Brick architecture represents
a 10K modular pod
• Add n pods for n-scale
• Use the Microsoft capacity
calculators and load-testing
tools to validate
Microsoft Infrastructure
https://docs.aws.amazon.com/quickstart/latest/accelerator-msservers/welcome.html
39. Enterprise Application Requirements
Security and Compliance
Availability and Resilliency (Reliability)
Cost optimised
Performance
https://aws.amazon.com/architecture/well-architected/
40. Best Practice Advice
Right size your resources
Transform where possible
Stay lean
Get some help
Invest in training
Quickstarts and the architecture centre